MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bdfc5b93705161e526cd29e186ea5f3e0211bfa5fbdc46b7a5867397bc4f6c3c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: bdfc5b93705161e526cd29e186ea5f3e0211bfa5fbdc46b7a5867397bc4f6c3c
SHA3-384 hash: d19d666eddf27762e82ff8c4257319f8ab09dffdee6c93e41a016f563335365c5955cdaab8ca5f24849cd112e3fdcc0a
SHA1 hash: f95358c87e6c629dbf6846ceec25afe69bfc0666
MD5 hash: 4845ad963a0f6fca2ada9a966eedd2ea
humanhash: connecticut-cup-three-indigo
File name:OILMARKTL QUOTATION.zip
Download: download sample
Signature AgentTesla
File size:604'876 bytes
First seen:2020-08-31 09:24:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:bPg1JI01mvMmd8HVQI8C+pVYkDzDIFmJ8o0twGbedTQeYEumrK:0nVaMVHVQI8hpADoKxedTQeYEuEK
TLSH 99D42315334EBE9445634CEB08D6E865C8BE803D2BA0BADD4AB473D990E319771B1DB3
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gains.hificlouds.com
Sending IP: 131.153.48.114
From: ME <sales@oilmarkntl.com>
Subject: RE:OILMARK - INSTRUMENTATION-ELECTRICAL-SAFETY-AUTOMATION SUPPLIER **(QUOTATION)**
Attachment: OILMARKTL QUOTATION.zip (contains "OILMARKTL QUOTATION.exe")

AgentTesla SMTP exfil server:
smtp.ritac-eg.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip bdfc5b93705161e526cd29e186ea5f3e0211bfa5fbdc46b7a5867397bc4f6c3c

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments